First published: Tue Apr 09 2019(Updated: )
Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote attackers to inject arbitrary web script in the browser of an internal user of the system by tricking them into inviting a follower on a document with a crafted name.
Credit: security@odoo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Odoo | <=12.0 | |
Odoo Odoo | <=12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-15635 is medium with a severity value of 6.1.
CVE-2018-15635 affects Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier.
An attacker can inject arbitrary web script in the browser of an internal user of the system by tricking them into inviting a follower on a document with a crafted payload.
To fix the vulnerability, update Odoo Community and Odoo Enterprise to versions 12.0 or later.
Yes, you can find more information about CVE-2018-15635 on the Odoo GitHub page: https://github.com/odoo/odoo/issues/32515